Skip to content

Management API Keys

Programmatic credentials for managing your AnyRouter account — keys, presets, BYOK, and credits.

Management keys (ak_…) let you administer your AnyRouter account from scripts, CI pipelines, or other tools — without your dashboard password. They authenticate the management plane: LLM key CRUD, presets, BYOK providers, credits, and your own management keys.

POST/api/v1/management-keys

A management key is authenticated by sending it as a Bearer token (Authorization: Bearer ak_live_…). Management keys are not for LLM inference — to call /api/v1/chat/completions or /api/v1/messages, use an LLM key (sk-ar-…) from /dashboard/keys.

Two kinds of keys

Key typePrefixPurposeWhere to manage
LLM API keyssk-ar-Send chat, messages, embeddings, image, and responses requests/dashboard/keys
Management API keysak_Programmatically manage your account: list/create/revoke LLM keys, configure BYOK, read credits/dashboard/management-keys

Request

Create a key from the dashboard (Create key → name it → select scopes → copy the secret shown once), or programmatically from a session-authed request:

FieldTypeRequiredDescription
namestringYesHuman-readable key name.
descriptionstringNoFree-text note (e.g. what uses the key).
scopesstring[]YesThe scopes this key grants (see below).
expires_atstringNoISO 8601 expiration timestamp.

Scopes

Scopes follow the action:resource pattern. write:X implicitly grants read:X. Grant the smallest set a key needs — a leaked read:credits-only key cannot create LLM keys or change BYOK.

ScopeGrants access to
read:llm-keysGET /api/v1/keys, GET /api/v1/key
write:llm-keysPOST /api/v1/keys, PATCH /api/v1/keys/{hash}, DELETE /api/v1/keys/{hash}
read:presetsGET /api/v1/presets, GET /api/v1/presets/{slug}
write:presetsPOST /api/v1/presets, PATCH /api/v1/presets/{slug}, DELETE /api/v1/presets/{slug}
read:byokGET /api/v1/auth/byok/...
write:byokPOST/PATCH/DELETE /api/v1/auth/byok/...
read:creditsGET /api/v1/credits
read:management-keysGET /api/v1/management-keys
write:management-keysPOST /api/v1/management-keys, DELETE /api/v1/management-keys/{id}

Other routes

Method & pathPurpose
GET /api/v1/management-keysList your management keys. Pass ?include_invalid=true to include revoked/expired keys.
DELETE /api/v1/management-keys/{id}Revoke a key immediately (optional revocation_reason body).

Response

POST /api/v1/management-keys returns the plaintext secret once — store it immediately. Revocation is immediate: the next request with a revoked key returns 401.

Examples

curl -X POST https://anyrouter.dev/api/v1/management-keys \
  -H "Content-Type: application/json" \
  --cookie "__session=<your-session-cookie>" \
  -d '{
    "name": "CI deploy bot",
    "description": "Used by the GitHub Actions deploy workflow",
    "scopes": ["read:credits", "write:llm-keys"],
    "expires_at": "2027-01-01T00:00:00Z"
  }'
curl https://anyrouter.dev/api/v1/credits \
  -H "Authorization: Bearer ak_live_..."
curl https://anyrouter.dev/api/v1/management-keys \
  -H "Authorization: Bearer ak_live_..."
curl -X DELETE https://anyrouter.dev/api/v1/management-keys/<key_id> \
  -H "Authorization: Bearer ak_live_..." \
  -H "Content-Type: application/json" \
  -d '{"revocation_reason": "Rotated for quarterly audit"}'

Organization-scoped keys

If your account belongs to an organization, keys you create while the org is active are owned by the org — any member with access can use them and revocation is org-wide. Personal keys are owned by your user and only authenticate you.

Store secrets in a secret manager (1Password, Vault, GitHub Actions Secrets), never in source control. Use the narrowest scope set, set an expires_at where possible, rotate on a schedule, and revoke any key you suspect is compromised.

Errors

StatusMeaningFix
401Key invalid, revoked, or expiredCreate a fresh key from the dashboard.
403Key valid but lacks the route's scopeAdd the required scope, or use a higher-scoped key.
  • API Keys — the sk-ar-… LLM keys these credentials manage
  • Credits API — read balance with read:credits
  • Presets API — manage presets with write:presets
  • BYOK — configure provider keys with write:byok